Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5

Size: px
Start display at page:

Download "Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5"

Transcription

1 Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5 Updated: May 10, 2010 This document includes the following sections: Introduction New Features New Guidelines Guidelines from Previous Releases Still in Effect System Requirements AnyConnect Support Policy Caveats Notices/Licensing Related Documentation Introduction These release notes are for the Cisco AnyConnect Secure Mobility Client, Release We have changed the name of the Cisco AnyConnect VPN Client to the Cisco AnyConnect Secure Mobility Client; the product name change is in transition, and may not be complete in all places. The Cisco AnyConnect Secure Mobility client provides remote users with secure VPN connections to the Cisco ASA 5500 Series Adaptive Security Appliance using the Secure Socket Layer (SSL) protocol and the Datagram TLS (DTLS) protocol. AnyConnect provides remote end users with the benefits of a Cisco SSL VPN client, and supports applications and functions unavailable to a clientless, browser-based SSL VPN connection. It runs on Microsoft Windows, Windows Mobile, Linux, and Mac OS X, and supports connections to IPv6 resources over an IPv4 network tunnel. You can upload the client to the ASA to automatically download Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA USA 2010 Cisco Systems, Inc. All rights reserved.

2 Downloading the Latest Version to remote users when they log in, or you can download and install it on the endpoint. You can configure the ASA to uninstall AnyConnect from the endpoint after the connection terminates, or it can remain on the remote PC for future SSL VPN connections. In addition to the Cisco Adaptive Security Appliance 5500 Series, Cisco IOS supports the AnyConnect Secure Mobility client. For more information, see the Cisco IOS SSL VPN Data Sheet. Downloading the Latest Version To download the latest version of AnyConnect, you must be a registered user of Cisco.com. Step 1 Step 2 Step 3 Follow this link to the Cisco AnyConnect Secure Mobility Client Introduction page: Enter your cisco.com credentials. Click Download Software Step 4 Expand the Latest Releases folder and click the Step 5 Step 6 Step 7 Step 8 We provide AnyConnect packages for Windows, Windows Mobile, Mac OS X, and Linux. If you would like to download all of the latest AnyConnect packages, click Download Now under anyconnect-all k9.zip. Click Proceed with Download. Select a download manager option and proceed with the download. Follow the instructions in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5 to install the packages onto an ASA. New Features AnyConnect 2.5 supports the following new features on Windows 7, Vista, and XP; and Mac OS X 10.5 and 10.6: Post Log-in Always-on VPN Connect Failure Policy Captive Portal Hotspot Detection Captive Portal Remediation Client Firewall with Local Printer and Tethered Device Support Optimal Gateway Selection Quarantine AnyConnect Profile Editor 2

3 New Features Post Log-in Always-on VPN As an administrator, you can configure AnyConnect to establish a VPN session automatically after the user logs in to a computer. The VPN session remains open until the user logs out of the computer. If the physical connection is lost, the session remains open, and AnyConnect continually attempts to reestablish the physical connection with the ASA to resume the VPN session. (Post log-in) always-on VPN enforces corporate policies to protect the computer from security threats by preventing access to Internet resources when it is not in a trusted network. Always-on VPN requires a valid server certificate configured on the ASA; otherwise, it fails and logs an event indicating the certificate is invalid. Caution Ensure your server certificates can pass strict mode if you configure always-on VPN. With always-on enabled, the client does not support connecting through a proxy. The ASA lets you configure dynamic access policies, group policies, or both to exempt certain individuals from an always-on VPN setting. If an AnyConnect policy enables always-on VPN and a dynamic access policy or group policy disables it, the client retains the disable setting for the current and future VPN sessions as long as its criteria match the dynamic access policy or group policy on the establishment of each new session. AnyConnect supports a Disconnect button for always-on VPN sessions. If you enable it, AnyConnect displays a Disconnect button upon the establishment of a VPN session. Users of always-on VPN sessions may want to click Disconnect so they can choose an alternative secure gateway for reasons such as the following: Performance issues with the current VPN session. Reconnection issues following the interruption of a VPN session. Caution For the reasons noted above, disabling the Disconnect button can at times hinder or prevent VPN access. Do not attempt to configure always-on VPN until you have read all of the instructions and understand its requirements and implications, as detailed in the following sections in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5: Post Log-in Always-on VPN Disconnect Button for Always-on VPN 3

4 New Features Connect Failure Policy The connect failure policy determines whether the computer can access the Internet if always-on VPN is enabled and AnyConnect cannot establish a VPN session (for example, when a secure gateway is unreachable). The fail-close policy disables network connectivity except for VPN access. The fail-open policy permits network connectivity. Regardless of the connect failure policy, AnyConnect continues to try to establish the VPN connection. The following table explains the fail open and fail close policies: Always-on VPN Connect Policy Scenario Advantage Trade-off Fail open Fail close AnyConnect fails to establish or reestablish a VPN session. This failure could occur if the secure gateway is unavailable, or if AnyConnect does not detect the presence of a captive portal (often found in airports, coffee shops and hotels). Same as above except that this option is primarily for exceptionally secure organizations where security persistence is a greater concern than always-available network access. Grants full network access, letting users continue to perform tasks where access to the Internet or other local network resources is needed. The endpoint is protected from web-based malware and sensitive data leakage at all times because all network access is prevented except for local resources such as printers and tethered devices permitted by split tunneling. Security and protection are not available until the VPN session is established. Therefore, the endpoint device may get infected with web-based malware or sensitive data may leak. Until the VPN session is established, this option prevents all network access except for local resources such as printers and tethered devices. It can halt productivity if users require Internet access outside the VPN and a secure gateway is inaccessible. Caution A connect failure closed policy prevents network access if AnyConnect fails to establish a VPN session. AnyConnect detects most captive portals, described in Captive Portal Hotspot Detection and Remediation section on page 29; however, if it cannot detect a captive portal, a connect failure closed policy prevents all network connectivity. If you deploy a closed connection policy, we highly recommend that you follow a phased approach. For example, first deploy always-on VPN with a connect failure open policy and survey users for the frequency with which AnyConnect does not connect seamlessly. Then deploy a small pilot deployment of a connect failure closed policy among early-adopter users and solicit their feedback. Expand the pilot program gradually while continuing to solicit feedback before considering a full deployment. As you deploy a connect failure closed policy, be sure to educate the VPN users about the network access limitation as well as the advantages of a connect failure closed policy. Do not attempt to configure a connect failure policy until you have read all of the instructions and understand the requirements and implications, as detailed in Connect Failure Policy for Always-on VPN in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5: 4

5 New Features Captive Portal Hotspot Detection Many facilities that offer Wi-Fi and wired access, such as airports, coffee shops, and hotels, require the user to pay before obtaining access, agree to abide by an acceptable use policy, or both. These facilities use a technique called captive portal to prevent applications from connecting until the user opens a browser and accepts the conditions for access. AnyConnect displays the Unable to contact VPN server message on the GUI if it cannot connect, regardless of the cause. If a captive portal is not present, AnyConnect continues to attempt to connect to the VPN and updates the status message accordingly. If always-on VPN is enabled, the connect failure policy is closed, captive portal remediation is disabled, and AnyConnect detects the presence of a captive portal, the AnyConnect GUI displays the following message once per connection and once per reconnect: The service provider in your current location is restricting access to the Internet. The AnyConnect protection settings must be lowered for you to log on with the service provider. Your current enterprise security policy does not allow this. If AnyConnect detects the presence of a captive portal and the AnyConnect configuration differs from that described above, the AnyConnect GUI displays the following message once per connection and once per reconnect: The service provider in your current location is restricting access to the Internet. You need to log on with the service provider before you can establish a VPN session. You can try this by visiting any website with your browser. Captive Portal Remediation Captive portal remediation is the process of satisfying the requirements of a captive portal hotspot to obtain network access. By default, the connect failure policy prevents captive portal remediation because it restricts network access. You can configure AnyConnect to lift restricted access to let the user satisfy the captive portal requirements. You can also specify the duration for which AnyConnect lifts restricted access. For instructions, see Captive Portal Remediation in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. Client Firewall with Local Printer and Tethered Device Support When users connect to the ASA, all traffic is tunneled through the connection and users cannot access resources on their local network. This includes printers, cameras, and Windows Mobile devices (tethered devices) that sync with the local computer. Enabling Local LAN Access in the client profile resolves this problem, however it can introduce a security or policy concern for some enterprises as a result of unrestricted access to the local network. You can use the ASA to deploy endpoint OS firewall capabilities to restrict access to particular types of local resources, such as printers and tethered devices. To do so, enable client firewall rules for specific ports for printing. The client distinguishes between inbound and outbound rules. For printing capabilities, the client opens ports required for outbound connections, but blocks all incoming traffic. The client firewall is independent of the always-on feature. Note Be aware that users logged in as administrators have the ability to modify the firewall rules deployed to the client by the ASA. Users with limited privileges cannot modify the rules. For either user, the client reapplies the rules when the connection terminates. 5

6 New Features If you configure the client firewall, and the user authenticates to an Active Directory (AD) server, the client still applies the firewall policies from the ASA. However, the rules defined in the AD group policy take precedence over the rules of the client firewall. Note Host Scan and some third-party firewalls can interfere with the firewall function configured on the ASA group policy. With third-party firewalls, traffic is passed only if both the AnyConnect client firewall and the third-party firewall permit the traffic type. If the third-party firewall blocks a specific traffic type that the AnyConnect client permits, the client blocks the traffic. Differences in Firewall Behavior between Mac and Windows For Windows computers, deny rules take precedence over allow rules in Windows Firewall. If the ASA pushes down an allow rule to the AnyConnect client, but the user has created a custom deny rule, the AnyConnect rule is not enforced. On Mac computers, the AnyConnect client applies rules sequentially in the same order the ASA applies them. Global rules should always be last. Windows users whose firewall service must be started by the AnyConnect client (not started automatically by the system) may experience a noticeable increase in the time it takes to establish a VPN connection. Due to limitations of the OS, the client firewall policy on computers running Windows XP is enforced for inbound traffic only. Outbound rules and bidirectional rules are ignored. This would include firewall rules such as 'permit ip any any'. For instructions on how to use the firewall to support local printers and tethered devices, see Client Firewall with Local Printer and Tethered Device Support in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5 Optimal Gateway Selection Using the Optimal Gateway Selection (OGS) feature, you can minimize latency for Internet traffic without user intervention. With OGS, the AnyConnect client identifies and selects which secure gateway is best for connection or reconnection. OGS begins upon first connection or upon a reconnection at least four hours after the previous disconnection. Users who travel to distant locations connect to a secure gateway nearer to the new location for better performance. Your home and office will get similar results from the same gateway, so no switch of secure gateways will typically occur in this instance. Connection to another secure gateway occurs rarely and only occurs if the performance improvement is at least 20%. Note You can configure these threshold values using the Profile Editor. By optimizing these values for your particular network, you can find the correct balance between selecting the optimal gateway and reducing the number of times to force the re-entering of credentials. OGS is not a security feature, and it performs no load balancing between secure gateway clusters or within clusters. You can optionally give the end user the ability to enable or disable the feature. The minimum round trip time (RTT) solution selects the secure gateway with the fastest RTT between the client and all other gateways. The client always reconnects to the last secure gateway if the time elapsed has been less than four hours. Factors such as load and temporary fluctuations of the network connection may affect the selection process, as well as the latency for Internet traffic. 6

7 New Features OGS supports computers running: Windows 7, Vista, and XP Mac OS X 10.5 and 10.6 You use the second Preferences menu option of the Profile Editor to control the activation and deactivation of the OGS and to specify whether end users may control the feature themselves. If OGS is enabled when the AnyConnect client GUI is started, Automatic Selection displays in the Connect To drop-down menu on the Cisco AnyConnect Connection tab. You cannot change this selection. OGS automatically chooses the optimal secure gateway and displays the selected gateway on the status bar. You may need to click Select to start the connection process. It contacts only the primary servers to determine the optimal one. Once determined, the connection algorithm is as follows: 1. Attempt connection to the optimal server. 2. If that fails, try the optimal server s backup server list. 3. If that fails, try each remaining server in the OGS selection list, as ordered by its selection results. If you made the feature user controllable, the user can manually override the selected secure gateway with the following steps: Step 1 Step 2 Step 3 If currently connected, click Disconnect. Open the Preferences tab and uncheck Enable Optimal Gateway Selection. Choose the desired secure gateway. Note If AAA is being used, end users may have to re-enter their credentials when transitioning to a different secure gateway. The use of certificates eliminates this. For more information about OGS, see Optimal Gateway Selection in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. Quarantine Through the use of quarantine, you can restrict a particular client who already has an established tunnel through a VPN. The ASA applies restricted ACLs to a session to form a restricted group, based on the selected dynamic access policy. When an endpoint is not compliant with an administratively defined policy, the user can still access services for remediation (such as updating the antivirus and so on), but restrictions are placed upon the session. After the remediation occurs, the user can reconnect, which invokes a new posture assessment. If this assessment passes, the user connects. Note Using the Reconnect button, the user can initiate a disconnect and start a new tunnel after remediation if always-on VPN is enabled. Quarantine requires an Advanced Endpoint Assessment license specified in the adaptive security license configuration. The advanced endpoint assessment remediates endpoints that do not comply with dynamic policy requirements for antivirus, antispyware, and firewall applications; and any associated 7

8 New Guidelines application definition file requirements. Advanced endpoint assessment is a Cisco Secure Desktop Host Scan feature, so AnyConnect supports quarantine on the OSs that the version of Cisco Secure Desktop supports. Go to Supported VPN Platforms and refer to the Cisco Secure Desktop section that identifies the release you are using. The table identifies the OSs that Host Scan supports. ASA Release 8.3(1) or later features dynamic access policies and group policies that support a user message to display on the AnyConnect UI for the duration of the quarantine state. Quarantine does not require the ASA upgrade; only the user message requires it. If you upgrade the ASA to 8.3(1), we recommend that you also upgrade ASDM to Release 6.3(1) or later so that you can use it to configure the new features. For instructions, see Using Quarantine to Restrict Non-Compliant Clients in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. AnyConnect Profile Editor The AnyConnect profile editor is a convenient GUI-based configuration tool you can use to configure the AnyConnect client profile an XML file containing settings that control client features. Previously, you could only change profile settings manually by editing the XML tags in the profile. The AnyConnect client software package for each operating system, version 2.5 and later, contains the profile editor. You can launch the profile editor from ASDM (version 6.3(1) or later) if the client software package is loaded on the ASA as an SSL VPN client image. Note If you do not upgrade ASDM to version 6.3(1) or later, use the XML examples in the following sections as a guide to modifying the AnyConnect profile to enable each feature. If you load multiple client packages, ASDM loads the profile editor from the newest client package. This approach ensures the editor displays the features for the newest client loaded, as well as the older clients. The Profile Editor supports only Java SE 1.6 on the client computer. To activate the profile editor in ASDM, load the AnyConnect client software package as an SSL VPN image and go to Configuration > Remote Access VPN > Network (Client) Access > AnyConnect Client Profile. For more information about using the profile editor, see the sections beginning with Introduction to the AnyConnect Profile Configuration in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. New Guidelines Please note the following guidelines: Change to AnyConnect Pop-Up Messages on page 9 Revocation Message on page 9 MTU Adjustment on Group Policy May Be Required for Mac OS on page 9 AnyConnect for Mac OS X Performance when Behind Certain Routers on page 9 Preventing Windows Users from Circumventing Always-on on page 10 8

9 New Guidelines Change to AnyConnect Pop-Up Messages For release 2.5, we created this new message displayed to AnyConnect users: AnyConnect cannot confirm it is connected to your secure gateway. The local network may not be trustworthy. Please try another network. Users receive the new message when the client cannot validate the certificate from the ASA for either of these reasons: An entity between the AnyConnect client and the ASA is giving the client an invalid certificate in order to sniff traffic (which could be a man-in-the-middle attack). Switching networks could alleviate the problem. You configured the server certificate incorrectly on the ASA. If this happened, and strict-mode is enabled, all users will experience this issue. You can resolve this by putting the proper server certificate on the ASA that can be validated by the AnyConnect client from the certificate authority. The new message replaces and consolidates the following messages displayed by releases 2.4 and earlier: Connection attempt has failed due to server certificate problem. Local policy prohibits the acceptance of untrusted server certificates. A VPN connection will not be established. Revocation Message An AnyConnect GUI revocation warning popup window opens after authentication if AnyConnect attempts to verify a server certificate that specifies the distribution point of an LDAP certificate revocation list (CRL) if the distribution point is only internally accessible. If you want to avoid the display of this popup window, do one of the following: Obtain a certificate without any private CRL requirements. Disable server certificate revocation checking in Internet Explorer. MTU Adjustment on Group Policy May Be Required for Mac OS AnyConnect on Mac OS sometimes receives and drops packet fragments with some routers. This can result in a failure of some web traffic to pass. To avoid this, lower the value of the MTU. To access the MTU with ASDM, choose Configuration > Network (Client) Access > Group Policies > Add or Edit > Advanced > SSL VPN Client. AnyConnect for Mac OS X Performance when Behind Certain Routers When the AnyConnect client for Mac OS X connects to the ASA from behind certain types of routers, such as the Cisco Virtual Office (CVO) router, some web traffic may pass through the connection while other traffic drops. This could happen because AnyConnect may calculate the MTU incorrectly. To work around this problem, set the MTU for the AnyConnect adaptor to a lower value using the following command from the OS X command line: sudo ipconfig cscotun0 mtu 1200 (For OS X 10.5 or earlier) sudo ipconfig utun0 mtu 1200 (For OS X 10.6 and later) 9

10 Guidelines from Previous Releases Still in Effect Preventing Windows Users from Circumventing Always-on On Windows computers, users with limited or standard privileges may sometimes have write access to their program data folders. This could allow them to delete the AnyConnect profile file and thereby circumvent the always-on feature. To prevent this, configure the computer to restrict access to the following folders (or at least the Cisco sub-folder): For Windows XP users: C:\Document and Settings\All Users For Windows Vista and Windows 7 users: C:\ProgramData Guidelines from Previous Releases Still in Effect The following guidelines documented for previous releases remain in effect for AnyConnect 2.5: Responding to a TUN/TAP Error Message with Mac OS X 10.5 on page bit Internet Explorer Not Supported on page 11 Avoid Wireless-Hosted-Network on page 11 AnyConnect Requires That the ASA Be Configured to Accept TLSv1 Traffic on page 11 Mac OS X 10.6 Sends All DNS Queries in the Clear on page 11 Flexibility in Sequence and Method Used to Install Start Before Logon and DART Components on page 11 Responding to a TUN/TAP Error Message with Mac OS X 10.5 During the installation of AnyConnect on Mac OS X 10.5 and earlier versions, the following error message sometimes appears: A version of the TUN virtual network driver is already installed on this system that is incompatible with the AnyConnect client. This is a known issue with OS X version 10.5 and prior, and has been resolved in Please uninstall any VPN client, speak with your System Administrator, or reference the AnyConnect Release Notes for assistance in resolving this issue. Mac OS X 10.6 resolves this issue because it provides the version of the TUN/TAP virtual network driver AnyConnect requires. Versions of Mac OS X earlier than 10.6 do not include a TUN/TAP virtual network driver, so AnyConnect installs its own on these operating systems. However, some software such as Parallels, software that manages data cards, and some VPN applications install their own TUN/TAP driver. The AnyConnect installation software displays the error message above because the driver is already present, but its version is incompatible with AnyConnect. To install AnyConnect, you must remove the TUN/TAP virtual network driver. Note Removing the TUN/TAP virtual network driver can cause issues with the software on your system that installed the driver in the first place. To remove the TUN/TAP virtual network driver, open the console application and enter the following commands: sudo rm -rf /Library/Extensions/tap.kext 10

11 Guidelines from Previous Releases Still in Effect sudo rm -rf /Library/Extensions/tun.kext sudo rm -rf /Library/StartupItems/tap sudo rm -rf /Library/StartupItems/tun sudo rm -rf /System/Library/Extensions/tun.kext sudo rm -rf /System/Library/Extensions/tap.kext sudo rm -rf /System/Library/StartupItems/tap sudo rm -rf /System/Library/StartupItems/tun After entering these commands, restart Mac OS, then re-install AnyConnect. 64-bit Internet Explorer Not Supported AnyConnect installation via WebLaunch does not support 64-bit versions of Internet Explorer. Please instruct users of x64 (64-bit) Windows versions supported by AnyConnect to use the 32-bit version of Internet Explorer or Firefox to install WebLaunch. (At this time, Firefox is available only in a 32-bit version.) Avoid Wireless-Hosted-Network Using the Windows 7 Wireless Hosted Network feature can make AnyConnect unstable. When using AnyConnect, we do not recommend enabling this feature or running front-end applications that enable it (e.g., Connectify or Virtual Router). AnyConnect Requires That the ASA Be Configured to Accept TLSv1 Traffic The AnyConnect client cannot establish a connection with the following ASA settings for ssl server-version : ssl server-version sslv3. ssl server-version sslv3-only. Mac OS X 10.6 Sends All DNS Queries in the Clear With split-dns enabled, Mac OS X 10.6 sends all DNS queries in the clear. It should send DNS queries targeting split-dns domains over the VPN session. Apple plans to resolve this issue in an upcoming update. Flexibility in Sequence and Method Used to Install Start Before Logon and DART Components Previously, in order to use the Start Before Logon components for Windows, the same installation method was required for both AnyConnect and the Start Before Logon components. Both needed to be pre-deployed or both needed to be web-deployed. AnyConnect Release 2.4 eliminates this requirement. 11

12 System Requirements This allows the client to be deployed by one method and, perhaps at a later time, the Start Before Logon components to be installed by the same or another method. The Start Before Logon component still has the requirement that AnyConnect be installed first. Another new behavior for AnyConnect Release 2.4 is that if SBL or DART is manually uninstalled from an endpoint that then connects, these components will be re-installed. This behavior will only occur if the head-end configuration specifies that these components be installed and the preferences (set on the endpoint) permit upgrades. Previously these components would not be re-installed in this scenario without uninstalling and re-installing AnyConnect. System Requirements AnyConnect 2.5 installations can coexist with other VPN clients, including IPsec clients, on all supported endpoints; however, we do not support running AnyConnect while other VPN clients are running. The following sections identify the minimum management and endpoint requirements: Security Appliance Software Requirements Microsoft Windows Linux Mac OS Windows Mobile Security Appliance Software Requirements AnyConnect does not support virtualization software such as VMWare for any platform or Parallels Desktop for Mac OS. AnyConnect 2.5 requires the following: ASA 8.0(2) or later. ASDM 6.1(3) or later. We recommend upgrading to ASDM 6.3(1) or later so that you can use the AnyConnect profile editor to configure many of the AnyConnect features. You can use ASDM 6.3(1) in combination with ASA 8.0(2) or later. If you choose not to upgrade ASDM, you must use an editor to add the XML tags to the AnyConnect profile if you want to deploy the new AnyConnect features. You must upgrade to ASA 8.3(1) if you want to do the following: Use the services supported by a Cisco IronPort Web Security Appliance license. These services let you enforce acceptable use policies and protect endpoints from websites found to be unsafe by granting or denying all HTTP and HTTPS requests. Deploy firewall rules. If you deploy always-on VPN, you might want to enable split tunneling and configure firewall rules to restrict network access to local printing and tethered mobile devices. Configure dynamic access policies or group policies to exempt qualified VPN users from an always-on VPN deployment. Configure dynamic access policies to display a message on the AnyConnect GUI when an AnyConnect session is in quarantine. The minimum supported version of Cisco Secure Desktop is 3.2(2) or later. 12

13 System Requirements Microsoft Windows For WebLaunch, use Internet Explorer 6.0 or later or Firefox 3.0+, and enable ActiveX or install Sun JRE Windows Versions Windows 7 (32-bit and 64-bit) AnyConnect requires a clean install if you upgrade from Windows XP to Windows 7. If you upgrade from Windows Vista to Windows 7, manually uninstall AnyConnect first, then after the upgrade, reinstall it manually or by establishing a web-based connection to a security appliance configured to install it. Uninstalling before the upgrade and reinstalling AnyConnect afterwards is necessary because the upgrade does not preserve the Cisco AnyConnect Virtual Adapter. AnyConnect is compatible with 3G data cards which interface with Windows 7 via a WWAN adapter. Windows Vista (32-bit and 64-bit) SP2 or Vista Service Pack 1 with KB AnyConnect requires a clean install if you upgrade from Windows XP to Windows Vista. Windows XP SP2 and SP3. Windows Requirements Pentium class processor or greater. x86 (32-bit) or x64 (64-bit) processors. 5 MB hard disk space. RAM: 256 MB for Windows XP. 512 MB for Windows Vista. 512 MB for Windows 7. Microsoft Installer, version 3.1. Linux AnyConnect supports only standalone installations on Linux. The following sections show the supported Linux distributions and requirements. Linux Distributions Red Hat Enterprise Linux 5 Desktop Ubuntu 9.x We do not validate other Linux distributions. We will consider requests to validate other Linux distributions for which you experience issues, and provide fixes at our discretion. Linux Requirements x86 instruction set. 32-bit or biarch 64-bit processor standalone mode only; web-based install/connect is not supported. 13

14 System Requirements 32 MB RAM. 20 MB hard disk space. Superuser privileges. libstdc++ users must have libstdc++ version (libstdc++.so.5) or higher, but below version 4. Firefox 2.0 or later with libnss3.so installed in /usr/local/lib, /usr/local/firefox/lib, or /usr/lib. Firefox must be installed in /usr/lib or /usr/local, or there must be a symbolic link in /usr/lib or /usr/local called firefox that points to the Firefox installation directory. libcurl 7.10 or later. openssl 0.9.7a or later. Java 5 (1.5) or later. Iced Tea is the default Java package on Fedora 8. The only version that works for web installation is Sun Java. You must install Sun Java and configure your browser to use that instead of the default package. zlib or later. gtk 2.0.0, gdk 2.0.0, libpango 1.0. iptables 1.2.7a or later. tun module supplied with kernel or 2.6. Note AnyConnect SMC 2.5 reportedly runs on 64-bit Linux, although we do not support it. Mac OS AnyConnect 2.4 supports the following versions of Mac OS: Mac OS X 10.5 Mac OS X 10.6, , and (each of these versions on 32-bit and 64-bit). AnyConnect requires 50MB of hard disk space. If you upgrade from one major Mac OS X release to another (for example 10.5 to 10.6), manually uninstall AnyConnect first, then after the upgrade, reinstall it manually or by establishing a web-based connection to a security appliance configured to install it. Uninstalling before the upgrade and reinstalling AnyConnect afterwards is necessary because the upgrade does not preserve the Cisco AnyConnect Virtual Adapter. Windows Mobile We designed AnyConnect 2.5 for compatibility with Windows Mobile 6.5, 6.1, 6.0 and 5.0 Professional and Classic for touch-screens only. Users have reported success with most touch-screens running these versions of Windows Mobile. However, to ensure interoperability, we guarantee compatibility only with the devices we test, as follows: HTC Imagio running Windows Mobile 6.5 HTC Tilt 2 running Windows Mobile 6.5 Samsung Epix running Windows Mobile

15 AnyConnect Support Policy Samsung Omnia running Windows Mobile 6.1 Samsung Saga running Windows Mobile 6.1 HTC Touch running Windows Mobile 6.0 HTC TyTN running Windows Mobile 5.0 AnyConnect Support Policy We support all AnyConnect software versions available on the Cisco AnyConnect VPN Software Download site; however, we provide fixes and enhancements only in maintenance or feature releases based on the most recently released version. Caveats Caveats describe unexpected behavior or defects in Cisco software releases. Note If you have an account with CCO, you can use Bug Navigator II to find caveats of any severity for any release. To reach Bug Navigator II on CCO, select Software & Support: Online Technical Support: Software Bug Toolkit or navigate to The following sections lists caveats with Severities 2 and 3: Open Caveats in AnyConnect 2.5 Caveats Resolved in AnyConnect 2.5 Open Caveats in AnyConnect 2.5 Table 1 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility client Release 2.5. Table 1 Open Caveats in Cisco AnyConnect Secure Mobility client Release 2.5 ID CSCsh51779 CSCsh69786 CSCsi00491 CSCsm69213 CSCsm76977 CSCsm92424 CSCsq02996 CSCtg07128 CSCsu08798 CSCsu52949 CSCsu70199 Headline Client-side proxy & AoN tunneling: must stop direct access to proxy. IPv6 link local addresses are not tunneled through AnyConnect Client. Standalone can connect to wrong ASA from within Secure Desktop Anyconnect does not perform auto route correction on Mac/Linux Improve content of our logging Random client DPD disconnects with McAfee HIPS SW. Auto-resume sometimes fails even though head-end not timed out. AnyConnect doesn't use IE's exp proxy svr settings telemetry URL req AnyConnect Linux with certs fails if browser master password defined. GUI pops up certificate warning prompts on every connection attempt. IPv6: Network error: windows has detected and IP address conflict. 15

16 Caveats Table 1 ID CSCsv49773 CSCsw28876 CSCsw37980 CSCsw97163 CSCsx21485 CSCsx25806 CSCsx48918 CSCsx62325 CSCsy34111 CSCsy48762 CSCsy98882 CSCsz56742 CSCta94621 CSCtb73073 CSCtb73259 CSCtb80457 CSCtc03052 CSCtc17266 CSCtc43955 CSCtc65842 CSCtc68735 CSCtd47640 CSCtd59583 CSCtd60540 CSCtd63809 CSCtd67178 CSCte41997 CSCte42921 CSCte46102 CSCte73957 CSCte73983 CSCte78570 CSCte81696 CSCte85697 CSCte96715 CSCte98165 Open Caveats in Cisco AnyConnect Secure Mobility client Release 2.5 (continued) Headline Multiple local profiles for SG may result in using wrong settings. AnyConnect: Need to reboot PC to get localization catalog to load. AC needs more certificate matching events. AC should not re-use tg cookie if group-url w/ new tg is being used. VPN agent caches cert information. XP IPV6: AnyConnect can't ping assigned IPV6 address. RDP+SBL: Unable to retrieve logon information to verify compliance Windows Mobile driver error with SVC rekey new-tunnel SVC MSIE proxy option auto does not work AnyConnect: Split tunnel does not work with Anyconnect Mobile SD Vault should allow AnyConnect Downloader from any temp folder Will not use certificates under certain ASA configuration Enable local LAN access not consistent with other split tunnel options Mac: VPN establishment allowed while multiple local users logged in Message Connection to the proxy server failed appears during reconnect AnyConnect and ASA need to negotiate time-to-wait for authentication SCEP fails in upgrade scenario Private-side proxy on OS X doesn't support per-protocol proxy Anyconnect stuck in Contacting Network and does not timeout Mac GUI crash with SCEP in FIPS mode WM: Long group combo box doesn't have arrows DART: Need additional logging to troubleshoot SBL and TND vpnagent exception in filtering code reported on WER Win 7: autoreconnect attempts after standby affects connectivity ASA: WebVPN Homepage does not launch with correct browser vpnagent BEX-buffer overflow exception in autoproxy code reported to WER vpndownloader error appears in CSD Vault Get Unresolved Gateway Address When Trying to Connect AnyConnect unable to browse websites when connected bad apple config causes session to hang on ASR1k after disconnect bad apple config may cause vpnagentd to fail AC needs to be more robust against missing non-essential registry keys AnyConnect client remote network host names leak to local network AnyConnect install fails with -vpn driver encountered an error- message Windows client fails to negotiate AES cipher when available only on gw VPNGina crashes due to assumption of chained version of 3rd-party GINA 16

17 Caveats Table 1 ID CSCtf04766 CSCtf06844 CSCtf09447 CSCtf19644 CSCtf20119 CSCtf20226 CSCtf23946 CSCtf48078 CSCtf52183 CSCtf56830 CSCtf61128 CSCtf75772 CSCtf81852 CSCtf90996 CSCtf96386 CSCtf98121 CSCtg01304 CSCtg01525 CSCtg02656 CSCtg04881 CSCtg24945 CSCtg25686 CSCtg30439 CSCtg31720 CSCtg31729 CSCtg37737 CSCtg45505 CSCtg52703 Open Caveats in Cisco AnyConnect Secure Mobility client Release 2.5 (continued) Headline AnyConnect uses Windows system locale instead of install language AnyConnect SCEP enrollment not working with ASA Per Group Cert Auth Issues seen after power loss with tunnel up With split-exclude, AC LocalLanAccess preference not enabled AnyConnect proxy not removed upon disconnect if SBL configured Make anyconnect DNS w/ split tunnel behavior for Mac same as windows Agent does not restore DNS Suffix search list if VA dies AnyConnect random disconnections SCEP enrollment on Mac makes private key exportable from keychain AC cert popup appears even when not requested by ASA Change AP, client does not get state change events for connected state Anyconnect with SBL. Login prompt is displayed before the service loads. Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host Anyconnect may fail to connect when launched from ipass Anyconnect fails when client certificate has empty Subject Split-tunneling: filtering needs to be enforced on the VPN adapter Anyconnect should have clear description for each error msg IgnoreProxy does not work with SBL VPN Downloader always aborts first SSL handshake AC Windows: Failure when reconnecting due to caching of the vpn gw IP AnyConnect fails to launch within a RDP connection with Always-on AnyConnect cannot use certificate from crypto card JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs w/o disconnection AnyConnect cannot parse PAC file and does not connect to endpoint VPN connection fails from network with unusual captive portal AnyConnect fails on Panasonic Toughbook when using wireless 17

18 Notices/Licensing Caveats Resolved in AnyConnect 2.5 Table 2 shows the caveats that AnyConnect Secure Mobility client Release 2.5 resolves. Table 2 Caveats Resolved in Cisco AnyConnect Secure Mobility client Release 2.5 ID CSCsz78112 CSCtb11342 CSCtb73046 CSCtc25178 CSCtc35990 CSCtc41770 CSCtc85374 CSCtd00525 CSCtd23416 CSCtd34579 CSCte63458 CSCtf38038 CSCtf16698 CSCtg33029 Headline Long-term fix for Anyconnect with IPv6: non-english Vista Global and user preferences files may get out of sync VPN establishment allowed while multiple local users logged in on Linux Fail to establish tunnel as route table verification fails XP with IPv6 Split-DNS: only requests of type A are tunneled in AnyConnect may fail to connect if split-tunnel-list is huge AnyConnect Profile Editor: View Backup Servers can cause ASDM Hang VPN Agent crashes when locale returns NULL string Linux: Disconnect hangs for minutes following resume from sleep CSD: Group-URL Fails w/ Pre-Login Policy & Hostscan User impersonation to retrieve proxy settings fails AC on OSX leaks ipv6 traffic that should be tunneled to rogue 6to4 gw MSIE Proxy Lockdown might get stuck after PC reload Schema needs updating for Certs Notices/Licensing See the following sections for Cisco AnyConnect Secure Mobility client license information. License Options For brief descriptions and example product numbers (SKUs) of the AnyConnect user license options, see Cisco Secure Remote Access: VPN Licensing Overview. For the latest detailed information about the AnyConnect user license options, see Managing Feature Licenses in the Cisco ASA 5500 Series Configuration Guide using the CLI, 8.2. End-User License Agreement For the end-user license agreement, go to: 18

19 Related Documentation OpenSSL/Open SSL Project This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit ( This product includes cryptographic software written by Eric Young This product includes software written by Tim Hudson For Open Source License information for this product, please see the following link: Related Documentation For more information, see the following documents: Navigating the Cisco ASA 5500 Series Documentation Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5 Cisco Secure Desktop Configuration Guide for Cisco ASA 5500 Series Administrators CCDE, CCENT, CCSI, Cisco Eos, Cisco Explorer, Cisco HealthPresence, Cisco IronPort, the Cisco logo, Cisco Nurse Connect, Cisco Pulse, Cisco SensorBase, Cisco StackPower, Cisco StadiumVision, Cisco TelePresence, Cisco TrustSec, Cisco Unified Computing System, Cisco WebEx, DCE, Flip Channels, Flip for Good, Flip Mino, Flipshare (Design), Flip Ultra, Flip Video, Flip Video (Design), Instant Broadband, and Welcome to the Human Network are trademarks; Changing the Way We Work, Live, Play, and Learn, Cisco Capital, Cisco Capital (Design), Cisco:Financed (Stylized), Cisco Store, Flip Gift Card, and One Million Acts of Green are service marks; and Access Registrar, Aironet, AllTouch, AsyncOS, Bringing the Meeting To You, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, CCSP, CCVP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Lumin, Cisco Nexus, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Collaboration Without Limitation, Continuum, EtherFast, EtherSwitch, Event Center, Explorer, Follow Me Browsing, GainMaker, ilynx, IOS, iphone, IronPort, the IronPort logo, Laser Link, LightStream, Linksys, MeetingPlace, MeetingPlace Chime Sound, MGX, Networkers, Networking Academy, PCNow, PIX, PowerKEY, PowerPanels, PowerTV, PowerTV (Design), PowerVu, Prisma, ProConnect, ROSA, SenderBase, SMARTnet, Spectrum Expert, StackWise, WebEx, and the WebEx logo are registered trademarks of Cisco and/or its affiliates in the United States and certain other countries. All other trademarks mentioned in this document or website are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1002R) Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental Cisco Systems, Inc. All rights reserved. 19

Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5

Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5 Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5 Updated: August 10, 2012 This document includes the following sections: Introduction Downloading the Latest Version Important AnyConnect,

More information

Release Notes for Cisco IronPort Email Security Plug-in 7.1

Release Notes for Cisco IronPort Email Security Plug-in 7.1 Release Notes for Cisco IronPort Email Security Plug-in 7.1 Revised: December 10, 2010 Contents These release notes contain information critical to upgrading and running the Cisco IronPort Email Security

More information

Release Notes for Cisco IronPort Email Security Plug-in 7.2

Release Notes for Cisco IronPort Email Security Plug-in 7.2 Release Notes for Cisco IronPort Email Security Plug-in 7.2 Revised: October 12, 2011 Contents These release notes contain information critical to installing and running the Cisco IronPort Email Security

More information

Quick Startup Installation Instructions. Overview. Important Information

Quick Startup Installation Instructions. Overview. Important Information Overview The Cisco AnyConnect VPN Client is the next-generation VPN client, providing remote users with secure VPN connections to Washington Regional Medical System s software applications and services.

More information

Release Notes for Cisco AnyConnect VPN Client, Release 2.4

Release Notes for Cisco AnyConnect VPN Client, Release 2.4 Release Notes for Cisco AnyConnect VPN Client, Release 2.4 Updated: January 4, 2010 This document includes the following sections: Introduction Retain VPN on Windows Logoff Feature Introduced in AnyConnect

More information

Cisco Unified Reporting Administration Guide

Cisco Unified Reporting Administration Guide This guide provides an overview of the Cisco Unified Reporting web application, describes how to use the application, and provides procedures for completing various reporting tasks. The guide, which serves

More information

Accessibility Guidelines for Cisco Unified Contact Center Management Portal

Accessibility Guidelines for Cisco Unified Contact Center Management Portal Accessibility Guidelines for Cisco Unified Contact Center Management Portal Release 8.0(1) February 2010 Corporate Headquarters Cisco System s, Inc. 170 West Tasman D riv e San Jose, CA 95134-1706 USA

More information

Configuring the SA 500 for Active Directory Authentication of VPN Clients 2. Establishing a SSL VPN Connection By Using a Different Port Number 35

Configuring the SA 500 for Active Directory Authentication of VPN Clients 2. Establishing a SSL VPN Connection By Using a Different Port Number 35 Application Note Configuring a Cisco SA 500 for Active Directory Authentication of SSL VPN Clients This application note document provides information on how to enable the authentication of SSL VPN Clients

More information

Cisco Data Center Virtualization Assessment Service

Cisco Data Center Virtualization Assessment Service Cisco Data Center Virtualization Assessment Service Prepare for End-to-End Virtualization of Your Data Center A proactive approach to virtualization helps maintain the application performance, security,

More information

Cisco AnyConnect Secure Mobility Client VPN User Messages, Release 3.1

Cisco AnyConnect Secure Mobility Client VPN User Messages, Release 3.1 Cisco AnyConnect Secure Mobility Client VPN User Messages, Release 3.1 October 15, 2012 The following user messages appear on the AnyConnect client GUI. A description follows each message, along with recommended

More information

Release Notes for Cisco Support Tools Release 2.4(1)

Release Notes for Cisco Support Tools Release 2.4(1) Release Notes for Cisco Support Tools Release 2.4(1) July 2009 Contents Introduction, page 1 System Requirements, page 2 New Features, page 4 Limitations and Restrictions, page 4 Important Notes, page

More information

Cisco IronPort Encryption Appliance 6.5.5 Release Notes

Cisco IronPort Encryption Appliance 6.5.5 Release Notes Cisco IronPort Encryption Appliance 6.5.5 Release Notes Published: August 30, 2011 Contents These release notes contain important information about running the latest version of the IronPort Encryption

More information

Transferring Files Using HTTP or HTTPS

Transferring Files Using HTTP or HTTPS Transferring Files Using HTTP or HTTPS First Published: May 5, 2005 Last Updated: May 14, 2009 Cisco IOS Release 12.4 provides the ability to transfer files between your Cisco IOS software-based device

More information

Cisco Director Class SAN Planning and Design Service

Cisco Director Class SAN Planning and Design Service Cisco Director Class SAN Planning and Design Service Improve data center infrastructure for accessing, managing, and protecting growing information resources. Mitigate risk and accelerate the deployment

More information

Cisco Virtual Desktop Infrastructure Planning and Design Service

Cisco Virtual Desktop Infrastructure Planning and Design Service Cisco Virtual Desktop Infrastructure Planning and Design Service Reduce IT costs and increase application availability, scalability, and manageability with a virtualized desktop solution The Cisco Virtual

More information

PCI Compliance: Improve Payment Security

PCI Compliance: Improve Payment Security PCI Compliance: Improve Payment Security The latest Payment Card Industry (PCI) Data Security Standards (DSS) for customer data give you more ways to address an evolving risk environment and meet PCI compliance

More information

Medical Data Exchange A New Approach to Healthcare Interoperability

Medical Data Exchange A New Approach to Healthcare Interoperability Medical Data Exchange A New Approach to Healthcare Interoperability Introduction The healthcare industry has reached a tipping point. Costs have escalated at an unprecedented rate in the United States

More information

Cisco AnyConnect Secure Mobility Solution Guide

Cisco AnyConnect Secure Mobility Solution Guide Cisco AnyConnect Secure Mobility Solution Guide This document contains the following information: Cisco AnyConnect Secure Mobility Overview, page 1 Understanding How AnyConnect Secure Mobility Works, page

More information

Secure Access Using VPN

Secure Access Using VPN Secure Access Using VPN WHAT IS CISCO SSL VPN? Cisco is the brand name of the VPN appliance (hardware). The SSL VPN stands for Secure Sockets Layer Virtual Private Network. SSL VPN is a service that allows

More information

AnyConnect VPN Client FAQ

AnyConnect VPN Client FAQ AnyConnect VPN Client FAQ Document ID: 107391 Questions Introduction What level of rights is required for the AnyConnect client? Is a reboot required after AnyConnect is installed/upgraded? Is it possible

More information

Cisco Unified Attendant Console Backup and Restore Guide

Cisco Unified Attendant Console Backup and Restore Guide Cisco Unified Attendant Console Backup and Restore Guide Revised: January 28, 2013, 2011, This document describes how to back up Cisco Unified Attendant Console server Version 9.0 (all Editions), and restore

More information

Symbian User Guide for Cisco AnyConnect Secure Mobility Client, Release 2.4

Symbian User Guide for Cisco AnyConnect Secure Mobility Client, Release 2.4 Symbian User Guide for Cisco AnyConnect Secure Mobility Client, Release 2.4 Updated: May 31, 2011 Contents This document describes the Cisco AnyConnect Secure Mobility Client 2.4 for devices running Symbian.

More information

AnyConnect VPN Client FAQ

AnyConnect VPN Client FAQ AnyConnect VPN Client FAQ Document ID: 107391 Contents Introduction Installation Software Upgrade Licensing Supported Devices Supported Software Log Messages Datagram Transport Layer Security (DTLS) Supported

More information

Configuring Cisco Unified Communications Manager for the NovaTec TransNova S3 Voice Gateway

Configuring Cisco Unified Communications Manager for the NovaTec TransNova S3 Voice Gateway Configuring Cisco Unified Communications Manager for the NovaTec TransNova S3 Voice Gateway This document describes how to configure Cisco Unified Communications Manager systems to use the NovaTec TransNova

More information

Cisco AnyConnect Secure Mobility Client Administrator Guide

Cisco AnyConnect Secure Mobility Client Administrator Guide Cisco AnyConnect Secure Mobility Client Administrator Guide Release 2.5 Updated: August 24, 2010 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

Authentication on the Cisco IronPort Web Security Appliance

Authentication on the Cisco IronPort Web Security Appliance Cisco IronPort Web Security Appliance White Paper Authentication on the Cisco IronPort Web Security Appliance Executive Summary Table of Contents 1 Executive Summary 2 Introduction 2 Authentication Protocals

More information

Cisco Smar t Busines s Communications System IP Phone Por tfolio

Cisco Smar t Busines s Communications System IP Phone Por tfolio Cisco Smar t Busines s Communications System IP Phone Por tfolio Rich voice conversations, stylish appearance, and support for business applications. The Cisco Smart Business Communications System (SBCS)

More information

Best Practices for Monitoring Cisco Unity Devices with Cisco Unified Operations Manager

Best Practices for Monitoring Cisco Unity Devices with Cisco Unified Operations Manager . Best Practices for Monitoring Cisco Unity Devices with Cisco Unified Operations Manager Copyright 2010 Cisco Systems, Inc. This document is Cisco Public Information. Page 1 of 16 Contents Introduction...

More information

Release Notes for Cisco AnyConnect VPN Client, Release 2.4

Release Notes for Cisco AnyConnect VPN Client, Release 2.4 Release Notes for Cisco AnyConnect VPN Client, Release 2.4 Published: October 14, 2009 This document includes the following sections: Introduction New Supported Platforms New Feature Overviews New Guidelines

More information

Hardware and System Software Specification for Cisco Unified Web and E-Mail Interaction Manager

Hardware and System Software Specification for Cisco Unified Web and E-Mail Interaction Manager Hardware and System Software Specification f Cisco Unified Web and E-Mail Interaction Manager F Unified Contact Center Express Release 4.2(5) October 2009 Americas Headquarters Cisco Systems, Inc. 170

More information

The SSL device also supports the 64-bit Internet Explorer with new ActiveX loaders for Assessment, Abolishment, and the Access Client.

The SSL device also supports the 64-bit Internet Explorer with new ActiveX loaders for Assessment, Abolishment, and the Access Client. WatchGuard SSL v3.2 Release Notes Supported Devices SSL 100 and 560 WatchGuard SSL OS Build 355419 Revision Date January 28, 2013 Introduction WatchGuard is pleased to announce the release of WatchGuard

More information

Cisco Unified Wireless IP Phone 7925G Accessory Guide

Cisco Unified Wireless IP Phone 7925G Accessory Guide Cisco Unified Wireless IP Phone 7925G Accessory Guide This guide describes the accessories that you can order for your Cisco Unified Wireless IP Phone 7925G. Contents This document contains these sections:

More information

Cisco Data Center Architecture Assessment Service

Cisco Data Center Architecture Assessment Service Cisco Data Center Architecture Assessment Service Align networks, computer systems, and storage devices. Increase the efficiency, adaptability, and scalability of your data center by deploying Cisco Data

More information

Cisco Unified Wireless IP Phone 7925G Accessory Guide

Cisco Unified Wireless IP Phone 7925G Accessory Guide Cisco Unified Wireless IP Phone 7925G Accessory Guide This guide describes the accessories that you can order for your Cisco Unified Wireless IP Phone 7925G. Contents This document contains these sections:

More information

Configuring SSL VPN on the Cisco ISA500 Security Appliance

Configuring SSL VPN on the Cisco ISA500 Security Appliance Application Note Configuring SSL VPN on the Cisco ISA500 Security Appliance This application note describes how to configure SSL VPN on the Cisco ISA500 security appliance. This document includes these

More information

Cisco IronPort M-Series Security Management Appliance

Cisco IronPort M-Series Security Management Appliance Cisco IronPort M-Series Security Management Appliance Flexible management and complete security control at the network gateway The Cisco IronPort M-Series security management appliance is the perfect complement

More information

Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn

Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn Revised: October 04, 2009, Introduction These release notes are for the following Cisco AnyConnect VPN Client releases: 2.3.2016 2.3.254 2.3.185

More information

Cisco Registered Envelope Recipient Guide

Cisco Registered Envelope Recipient Guide September 8, 2008 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 Text Part Number:

More information

DOE VPN Client Installation and Setup Guide March 2011

DOE VPN Client Installation and Setup Guide March 2011 DOE VPN Client Installation and Setup Guide March 2011 Table of Contents Introduction... 3 System Requirements... 3 Microsoft Windows... 3 Mac OS X... 4 Windows... 4 Installation for the Cisco AnyConnect

More information

Terminal Services Overview

Terminal Services Overview Terminal Services Overview This chapter provides an overview of Cisco IOS terminal services and includes the following main sections: Cisco IOS Network Access Devices Line Characteristics and s Asynchronous

More information

Network Connect Installation and Usage Guide

Network Connect Installation and Usage Guide Network Connect Installation and Usage Guide I. Installing the Network Connect Client..2 II. Launching Network Connect from the Desktop.. 9 III. Launching Network Connect Pre-Windows Login 11 IV. Installing

More information

WatchGuard SSL v3.2 Update 1 Release Notes. Introduction. Windows 8 and 64-bit Internet Explorer Support. Supported Devices SSL 100 and 560

WatchGuard SSL v3.2 Update 1 Release Notes. Introduction. Windows 8 and 64-bit Internet Explorer Support. Supported Devices SSL 100 and 560 WatchGuard SSL v3.2 Update 1 Release Notes Supported Devices SSL 100 and 560 WatchGuard SSL OS Build 445469 Revision Date 3 April 2014 Introduction WatchGuard is pleased to announce the release of WatchGuard

More information

Design Guide for the Cisco Unified Videoconferencing Solution Using Desktop Component Release 7.1

Design Guide for the Cisco Unified Videoconferencing Solution Using Desktop Component Release 7.1 Design Guide for the Cisco Unified Videoconferencing Solution Using Desktop Component Release 7.1 May 2010 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.0

Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.0 Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.0 Last Updated: September 23, 2011 This document includes the following sections: Introduction, page 2 Downloading the Latest Version

More information

Cisco TelePresence Solutions

Cisco TelePresence Solutions Cisco TelePresence Solutions To excel in today s economy you have to collaborate with colleagues, partners, and customers around the globe at a moment s notice. You must continuously innovate and focus

More information

System Message Logging

System Message Logging System Message Logging This module describes how to configure system message logging on your wireless device in the following sections: Understanding System Message Logging, page 1 Configuring System Message

More information

Clientless SSL VPN Users

Clientless SSL VPN Users Manage Passwords, page 1 Username and Password Requirements, page 3 Communicate Security Tips, page 3 Configure Remote Systems to Use Clientless SSL VPN Features, page 3 Manage Passwords Optionally, you

More information

Cipher Suites and WEP

Cipher Suites and WEP Cipher Suites and WEP This module describes how to configure the cipher suites required for using Wireless Protected Access (WPA) and Cisco Centralized Key Management (CCKM); Wired Equivalent Privacy (WEP);

More information

How To Use A Cisco Vpn Client On A Pc Or Ipad (For A Network) On A Network (For Free) On Your Computer Or Ipod Or Ipo (For Cheap) On An Ipo Or Ipor (For

How To Use A Cisco Vpn Client On A Pc Or Ipad (For A Network) On A Network (For Free) On Your Computer Or Ipod Or Ipo (For Cheap) On An Ipo Or Ipor (For Release Notes for Cisco VPN Client, Release 5.0.06 Updated November 23, 2009 Part No. These release notes address the following subjects: Introduction Changes to Platforms Supported by this Release, page

More information

Tutorial: Assigning Prelogin Criteria to Policies

Tutorial: Assigning Prelogin Criteria to Policies CHAPTER 4 This tutorial provides an overview of the CSD configuration sequence. The configuration chapters that follow provide detailed instructions on the attributes. The sections are as follows: Overview

More information

Cisco AnyConnect VPN Client Administrator Guide

Cisco AnyConnect VPN Client Administrator Guide Cisco AnyConnect VPN Client Administrator Guide Version 2.0 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS

More information

Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn

Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn Revised: August 03, 2009, Introduction These release notes are for the following Cisco AnyConnect VPN Client releases: 2.3.2016 2.3.254 2.3.185

More information

Release Notes for Cisco IronPort AsyncOS 7.3.1 for Email

Release Notes for Cisco IronPort AsyncOS 7.3.1 for Email Release Notes for Cisco IronPort AsyncOS 7.3.1 for Email Revised: February 15, 2012 Contents These release notes contain information critical to upgrading and running Cisco IronPort AsyncOS 7.3.1 for Email,

More information

User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream

User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream User Manual Onsight Management Suite Version 5.1 Another Innovation by Librestream Doc #: 400075-06 May 2012 Information in this document is subject to change without notice. Reproduction in any manner

More information

Installation Guide for Cisco Unified Videoconferencing Manager Release 7.1

Installation Guide for Cisco Unified Videoconferencing Manager Release 7.1 Installation Guide for Cisco Unified Videoconferencing Manager Release 7.1 February 2010 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

Cisco Smart Care Services Questions and Answers About the Voice Quality Monitor Service

Cisco Smart Care Services Questions and Answers About the Voice Quality Monitor Service Cisco Smart Care Services Questions and Answers About the Voice Quality Monitor Service For Qualified Cisco Partners October 2008 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose,

More information

How To Install A Cisco Cisco Cs3.3.2.3 (Windows) On A Hard Drive With A Harddrive (Windows 3.3) On An External Hard Drive (Windows 2003) On Your Computer (Windows 2007)

How To Install A Cisco Cisco Cs3.3.2.3 (Windows) On A Hard Drive With A Harddrive (Windows 3.3) On An External Hard Drive (Windows 2003) On Your Computer (Windows 2007) Cisco UCS B-Series Blade Servers Windows Installation Guide October 06, 2010 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000

More information

Cisco Aironet Dual Band MIMO Low Profile Ceiling Mount Antenna (AIR-ANT2451NV-R)

Cisco Aironet Dual Band MIMO Low Profile Ceiling Mount Antenna (AIR-ANT2451NV-R) Cisco Aironet Dual Band MIMO Low Profile Ceiling Mount Antenna (AIR-ANT2451NV-R) This document outlines the specifications for the AIR-ANT2451NV-R dual band MIMO low profile ceilng mount antenna and provides

More information

Architecture and Data Flow Overview. BlackBerry Enterprise Service 10 721-08877-123 Version: 10.2. Quick Reference

Architecture and Data Flow Overview. BlackBerry Enterprise Service 10 721-08877-123 Version: 10.2. Quick Reference Architecture and Data Flow Overview BlackBerry Enterprise Service 10 721-08877-123 Version: Quick Reference Published: 2013-11-28 SWD-20131128130321045 Contents Key components of BlackBerry Enterprise

More information

Verizon Remote Access User Guide

Verizon Remote Access User Guide Version 17.12 Last Updated: August 2012 2012 Verizon. All Rights Reserved. The Verizon names and logos and all other names, logos, and slogans identifying Verizon s products and services are trademarks

More information

Symantec Integrated Enforcer for Microsoft DHCP Servers Getting Started Guide

Symantec Integrated Enforcer for Microsoft DHCP Servers Getting Started Guide Symantec Integrated Enforcer for Microsoft DHCP Servers Getting Started Guide Legal Notice Copyright 2006 Symantec Corporation. All rights reserved. Federal acquisitions: Commercial Software - Government

More information

Cisco AnyConnect Secure Mobility Client Administrator Guide

Cisco AnyConnect Secure Mobility Client Administrator Guide Cisco AnyConnect Secure Mobility Client Administrator Guide Release 3.0 Last Updated: September 14, 2011 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

Cisco ACE Web Application Firewall User Guide

Cisco ACE Web Application Firewall User Guide Cisco ACE Web Application Firewall User Guide Software Version 6.1 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800

More information

To participate in the hands-on labs in this class, you need to bring a laptop computer with the following:

To participate in the hands-on labs in this class, you need to bring a laptop computer with the following: Course: Deploying Cisco ASA VPN Solutions Duration: 5 Day Hands-On Lab & Lecture Course Price: $ 3,495.00 Learning Credits: 35 Description: The Deploying Cisco ASA VPN Solutions (VPN) v2.0 course is a

More information

Release Notes for Cisco IronPort AsyncOS 7.1.1 for Email

Release Notes for Cisco IronPort AsyncOS 7.1.1 for Email Release Notes for Cisco IronPort AsyncOS 7.1.1 for Email Published: May 20, 2010 Revised: June 9, 2010, Contents These release notes contain information critical to upgrading and running Cisco IronPort

More information

BlackBerry Enterprise Service 10. Version: 10.2. Configuration Guide

BlackBerry Enterprise Service 10. Version: 10.2. Configuration Guide BlackBerry Enterprise Service 10 Version: 10.2 Configuration Guide Published: 2015-02-27 SWD-20150227164548686 Contents 1 Introduction...7 About this guide...8 What is BlackBerry Enterprise Service 10?...9

More information

Citrix Access Gateway Plug-in for Windows User Guide

Citrix Access Gateway Plug-in for Windows User Guide Citrix Access Gateway Plug-in for Windows User Guide Access Gateway 9.2, Enterprise Edition Copyright and Trademark Notice Use of the product documented in this guide is subject to your prior acceptance

More information

Citrix Access on SonicWALL SSL VPN

Citrix Access on SonicWALL SSL VPN Citrix Access on SonicWALL SSL VPN Document Scope This document describes how to configure and use Citrix bookmarks to access Citrix through SonicWALL SSL VPN 5.0. It also includes information about configuring

More information

Cisco WAP4410N Wireless-N Access Point: PoE/Advanced Security Cisco Small Business Access Points

Cisco WAP4410N Wireless-N Access Point: PoE/Advanced Security Cisco Small Business Access Points Cisco WAP4410N Wireless-N Access Point: PoE/Advanced Security Cisco Small Business Access Points Advanced, High-Performance Wireless Access for the Small Business Highlights Supports high-bandwidth applications

More information

Release Notes for Cisco IronPort Email Security Plug-in 7.3.1

Release Notes for Cisco IronPort Email Security Plug-in 7.3.1 Release Notes for Cisco IronPort Email Security Plug-in 7.3.1 Revised: September 18, 2013 Contents These release notes contain information critical to installing and running the Cisco IronPort Email Security

More information

Cisco 100-Megabit Ethernet SFP Modules Compatibility Matrix

Cisco 100-Megabit Ethernet SFP Modules Compatibility Matrix Cisco 100-Megabit Ethernet SFP Modules Compatibility Matrix This document contains information about the Cisco platforms and software versions that support the 100-Megabit Ethernet Small Form-Factor Pluggable

More information

ASA 8.x: VPN Access with the AnyConnect VPN Client Using Self Signed Certificate Configuration Example

ASA 8.x: VPN Access with the AnyConnect VPN Client Using Self Signed Certificate Configuration Example ASA 8.x: VPN Access with the AnyConnect VPN Client Using Self Signed Certificate Configuration Example Document ID: 99756 Contents Introduction Prerequisites Requirements Components Used Conventions Background

More information

Cisco Unified IP Phone 6901 and 6911 User Guide for Cisco Unified Communications Manager 8.0 (SCCP)

Cisco Unified IP Phone 6901 and 6911 User Guide for Cisco Unified Communications Manager 8.0 (SCCP) Cisco Unified IP Phone 6901 and 6911 User Guide for Cisco Unified Communications Manager 8.0 (SCCP) Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

SSL VPN Service. Once you have installed the AnyConnect Secure Mobility Client, this document is available by clicking on the Help icon on the client.

SSL VPN Service. Once you have installed the AnyConnect Secure Mobility Client, this document is available by clicking on the Help icon on the client. Contents Introduction... 2 Prepare Work PC for Remote Desktop... 4 Add VPN url as a Trusted Site in Internet Explorer... 5 VPN Client Installation... 5 Starting the VPN Application... 6 Connect to Work

More information

SonicWALL Mobile Connect. Mobile Connect for OS X 3.0. User Guide

SonicWALL Mobile Connect. Mobile Connect for OS X 3.0. User Guide SonicWALL Mobile Connect Mobile Connect for OS X 3.0 User Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your system. CAUTION: A CAUTION

More information

Clientless SSL VPN End User Set-up

Clientless SSL VPN End User Set-up 37 CHAPTER This ections is for the system administrator who sets up Clientless (browser-based) SSL VPN for end users. It summarizes configuration requirements and tasks for the user remote system. It also

More information

MITA End-User VPN Troubleshooting Guide

MITA End-User VPN Troubleshooting Guide 01. Introduction MITA VPN users can be assigned one of two types of profiles Client-Based or Web-Based, depending on the type of access required. When logging on to the MITA VPN Portal https://vpn.secure.gov.mt,

More information

Technical Brief for Windows Home Server Remote Access

Technical Brief for Windows Home Server Remote Access Technical Brief for Windows Home Server Remote Access Microsoft Corporation Published: October, 2008 Version: 1.1 Abstract This Technical Brief provides an in-depth look at the features and functionality

More information

For Sales Kathy Hall 402-963-4466 [email protected]

For Sales Kathy Hall 402-963-4466 khall@it4e.com IT4E Schedule 13939 Gold Circle Omaha NE 68144 402-431-5432 Course Number Course Name Course Description For Sales Chris Reynolds 402-963-4465 [email protected] www.it4e.com v2.0 SKY Deploying Cisco ASA

More information

Table of Contents. Cisco Cisco VPN Client FAQ

Table of Contents. Cisco Cisco VPN Client FAQ Table of Contents Cisco VPN Client FAQ...1 Questions...1 Introduction...2 Q. Why does the VPN Client disconnect after 30 minutes? Can I extend this time period?...2 Q. I upgraded to Mac OS X 10.3 (known

More information

DameWare Server. Administrator Guide

DameWare Server. Administrator Guide DameWare Server Administrator Guide About DameWare Contact Information Team Contact Information Sales 1.866.270.1449 General Support Technical Support Customer Service User Forums http://www.dameware.com/customers.aspx

More information

Ajera 7 Installation Guide

Ajera 7 Installation Guide Ajera 7 Installation Guide Ajera 7 Installation Guide NOTICE This documentation and the Axium software programs may only be used in accordance with the accompanying Axium Software License and Services

More information

new Business Online Technical Troubleshooting Guide

new Business Online Technical Troubleshooting Guide new Business Online Technical Troubleshooting Guide TABLE OF CONTENTS How to install Java 1.6 Page 3 How to install Java 1.6 without ActiveX control Page 6 How to uninstall Java Runtime Environment Page

More information

Connecting Cisco Fast Ethernet ISDN PRI Network Modules to the Network

Connecting Cisco Fast Ethernet ISDN PRI Network Modules to the Network Connecting Cisco Fast Ethernet ISDN PRI Network Modules to the Network Revised: May 1, 2008, OL-12808-01 This guide describes how to connect Cisco Fast Ethernet Integrated Services Digital Network (ISDN)

More information

Cisco Network Planning Solution 2.0.2 Documentation Guide and Supplemental License Agreement

Cisco Network Planning Solution 2.0.2 Documentation Guide and Supplemental License Agreement Cisco Network Planning Solution 2.0.2 Documentation Guide and Supplemental License Agreement June 2007 This documentation guide contains the End User Supplemental License Agreement for Cisco Systems Network

More information

Juniper NetScreen IPSec Dial Client. Installation Guide for Windows 2000 Windows XP Windows Vista

Juniper NetScreen IPSec Dial Client. Installation Guide for Windows 2000 Windows XP Windows Vista Juniper NetScreen IPSec Dial Client Installation Guide for Windows 2000 Windows XP Windows Vista Revision 2.0 NetScreen is a registered trademark of Juniper, Inc. Windows is a registered trademark of Microsoft

More information

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note BlackBerry Enterprise Service 10 Secure Work Space for ios and Android Version: 10.1.1 Security Note Published: 2013-06-21 SWD-20130621110651069 Contents 1 About this guide...4 2 What is BlackBerry Enterprise

More information

Cisco Registered Envelope Recipient Guide

Cisco Registered Envelope Recipient Guide February, 2012 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 Text Part Number:

More information

Allworx OfficeSafe Operations Guide Release 6.0

Allworx OfficeSafe Operations Guide Release 6.0 Allworx OfficeSafe Operations Guide Release 6.0 No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by any means, electronic, mechanical, photocopy,

More information

Dell SonicWALL SRA 7.5 Citrix Access

Dell SonicWALL SRA 7.5 Citrix Access Dell SonicWALL SRA 7.5 Citrix Access Document Scope This document describes how to configure and use Citrix bookmarks to access Citrix through Dell SonicWALL SRA 7.5. It also includes information about

More information

Configure Posture. Note. Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.1 1

Configure Posture. Note. Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.1 1 The AnyConnect Secure Mobility Client offers an ASA Posture Module and an ISE Posture Module. Both provide the Cisco AnyConnect Secure Mobility Client with the ability to assess an endpoint's compliance

More information

Installation Guide for Cisco Unified ICM/Contact Center Enterprise and Hosted Release 9.0(1)

Installation Guide for Cisco Unified ICM/Contact Center Enterprise and Hosted Release 9.0(1) Installation Guide for Cisco Unified ICM/Contact Center Enterprise and Hosted Release 9.0(1) First Published: June 21, 2012 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA

More information

FileMaker Server 14. FileMaker Server Help

FileMaker Server 14. FileMaker Server Help FileMaker Server 14 FileMaker Server Help 2007 2015 FileMaker, Inc. All Rights Reserved. FileMaker, Inc. 5201 Patrick Henry Drive Santa Clara, California 95054 FileMaker and FileMaker Go are trademarks

More information

Configuration Information

Configuration Information This chapter describes some basic Email Security Gateway configuration settings, some of which can be set in the first-time Configuration Wizard. Other topics covered include Email Security interface navigation,

More information

Getting Started. Symantec Client Security. About Symantec Client Security. How to get started

Getting Started. Symantec Client Security. About Symantec Client Security. How to get started Getting Started Symantec Client Security About Security Security provides scalable, cross-platform firewall, intrusion prevention, and antivirus protection for workstations and antivirus protection for

More information

Securing Networks with Cisco Routers and Switches (642-637)

Securing Networks with Cisco Routers and Switches (642-637) Securing Networks with Cisco Routers and Switches (642-637) Exam Description: The 642-637 Securing Networks with Cisco Routers and Switches exam is the exam associated with the CCSP, CCNP Security, and

More information